VDB
Sign up
HIGH

GHSA-4v58-74mf-rjx3

RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client

Quick fix

GHSA-4v58-74mf-rjx3 — github.com/rabbitmq/amqp091-go: upgrade to the fixed version with the command below.

go get github.com/rabbitmq/amqp091-go@v1.13.0

Details

**Summary** A vulnerability in the readField function allows a malicious or compromised AMQP server to trigger an unhandled runtime panic in the client application, leading to an immediate crash of the entire process.

**Details** When parsing incoming AMQP frames, the `readField` function processes byte-array fields (type tag `'x'`) by reading a 32-bit big-endian integer to determine the length of the data payload.

```go // read.go:253-263 case 'x': var len int32 if err = binary.Read(r, binary.BigEndian, &len); err != nil { return nil, err } value := make([]byte, len) // PANICS if len < 0 ```

If a server transmits a length value of `0xFFFFFFFF`, it is interpreted by the client as a signed 32-bit integer with a value of `-1`. Passing a negative integer to Go's built-in make() function for slice allocation triggers an unrecoverable runtime panic (panic: len out of range).

Because the reader goroutine handles network I/O without an explicit recover() wrapper, this panic propagates up to the runtime root, abruptly terminating the host application.

**Attack Vector / Exploitation Scenario** An attacker capable of spoofing, compromising, or controlling an AMQP broker can exploit this flaw during two primary phases:

1. Connection Establishment: Sending a malicious connection.start handshake frame containing server-properties with an 'x' type field assigned a negative length. 2. Message Delivery: Delivering a message payload where the header table contains a malformed field matching the criteria above.

**Impact** Availability: High. A single malformed frame can reliably crash the client process, resulting in a persistent Denial of Service (DoS) if the client automatically reconnects and receives the same payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/rabbitmq/amqp091-go
Introduced in: 0Fixed in: 1.13.0
Fixgo get github.com/rabbitmq/amqp091-go@v1.13.0

References